CVE-2023-6195 Details
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.
A server-side request forgery (SSRF) vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 15.5 prior to 16.9.7, 16.10 prior to 16.10.5, and 16.11 prior to 16.11.2. The vulnerability arises when the GitHub importer fetches markdown image links from issues, allowing an attacker to redirect requests to malicious URLs. This exploitation can be achieved by manipulating the image link to point to an attacker-controlled domain, which the GitLab server would then access, potentially leading to unauthorized data exposure or interaction with internal services.
Users can upgrade to GitLab versions 16.11.2, 16.10.5, or 16.9.7 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/432276 | [email protected] | ExploitIssue Tracking |
| https://hackerone.com/reports/2249268 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gitlab gitlab | >= 15.5.0, < 16.9.7 >= 16.10.0, < 16.10.5 >= 16.11.0, < 16.11.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | Initial Analysis | [email protected] |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | New CVE Received | [email protected] |